Hi,
A growth this big means someone deletes / change files very frequently.
If you can't find the cause, you can maybe try and fiddle with the snapdiff API - https://www.slideshare.net/AshwinPawar/snapdiff-150649347
Once you found the "offender", You need to understand what they do and why.
In my environment I usually keep the snap-reserve configuration to be very low and use AIUM (OCUM) to monitor breaches as an indicator for ransomware and intentional/accidental deletion. That's also how I found a case where a developer compress existing files again and again (to hourly, then daily, then weekly and monthly zip archives). Ideally this kind of activity need to be moved to a low retention volume, and once the files been fully processed - moved to long retention volume.